Allocation of Resources Without Limits or Throttling in Next.js - CVE-2026-44577
Published: May 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the Image Optimization API when handling requests to the /_next/image endpoint for large local assets matching configured local patterns. A remote attacker can request large local assets to cause a denial of service.
Only self-hosted deployments using the default image loader are vulnerable. By default, all local patterns are allowed.
Affected software
Event Processing
Maximo Application Suite - Monitor Component
How to mitigate CVE-2026-44577
Event Processing - update to 1.5.5
Maximo Application Suite - Monitor Component - addressed in versions 9.0.22, 9.1.12